PT-2021-5054 · Cisco · Cisco Access Points+1

Richard Atkin

·

Published

2021-09-22

·

Updated

2023-12-29

·

CVE-2021-1419

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Access Points (APs) (affected versions not specified)
Description A vulnerability in the SSH management feature could allow a local, authenticated user to modify files on the affected device and possibly gain escalated privileges. The issue is due to improper checking on file operations within the SSH management interface. A network administrator user could exploit this by accessing an affected device through SSH management to make a configuration change, potentially gaining privileges equivalent to the root user.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2021-05826
CVE-2021-1419

Affected Products

Cisco Access Points
Cisco Wls